International Journal of Computer Networks & Communications (IJCNC)

AIRCC PUBLISHING CORPORATION

IJCNC 02

CONTEXT-AWARE, GRAPH-CENTRIC AND ROBUSTNESS-GOVERNED INTRUSION DETECTION FRAMEWORK FOR VEHICULAR NETWORKS

Sandeep Girijashankar Shukla1 and Dr. Monika Bhatnagar2

1Research Scholar, Department of Computer Science & Engineering, Oriental University, Indore, Madhya Pradesh, 453555, India

2Research Supervisor, Department of Computer Science & Engineering, Oriental University, Indore, Madhya Pradesh, 453555, India

ABSTRACT

An abundance of cyber-physical communication ecosystems can be found in modern automobiles. The interactions between CAN, ECU, and V2X create attack paths that flat intrusion labels or accuracy-only IDS evaluation can’t safely handle in the process. The purpose of this research is to provide a five-stage intrusion detection approach for automotive networks that is aware of the context, centered on graphs, and regulated by robustness. Threat-Graph Entropy Mining (TGEM) is the initial component of the framework that has been developed. Attack surfaces, protocol artifacts, ECUs, and observable symptoms are all connected to one another through a multi-layer threat interaction graph in this procedure. Then, entropycentrality scoring finds the main attack families and unsolved defense gaps. The payload, temporal, and topological views are then aligned into a threat-priority-guided latent model via CMV-DD. This is accomplished by having the instructor and students distill the data. The Graph-TCN Transformer with Reliability-Gated Fusion (GTT-RGF) finds threats by combining ECU relationships, short-term temporal deviations, and long-range planned attack patterns. In order to accomplish this, it dynamically reduces the impact of views that are either fraudulent or highly noisy. When a minimum attack is utilized in a manner that is consistent with the graph, Counterfactual Attack-Path Verification (CAPV) monitors the situation to determine whether or not the alarms continue to be reliable. Under the Risk Calibration and Continuous Drift Governance (RCC-DG) system, detection data are converted into practical risk scores that are more precise. Additionally, the technology enables regulated updates to be made after drift has occurred. The findings of tests that were conducted with settings that were influenced by CAN and V2X revealed that F1- scores ranged from 93.9 to 96.2% in highway, urban, intersection, and mixed driving scenarios. Depending on the amount of traffic on the network, this indicates that the percentage of false positives decreases to between 1.9 and 3.1%. The model also has an average detection latency of 18–27 ms, a throughput of nearly 940 windows per second, a robust detection range of 88.9–90.6% under minor coordinated perturbations, an expected calibration error of 0.03 ms, and 95.6% performance retention after drift. Findings such as these demonstrate that the proposed paradigm not only improves the accuracy of detection, but also improves causal robustness, contextual generalization, risk interpretability, and implementation reliability for the next generation of intelligent transportation systems.

KEYWORDS

Vehicular Intrusion Detection, Threat Graph Mining, Context-Aware Learning, Multi-View Distillation, Robustness-Governed Security, Process

1. INTRODUCTION

Modern vehicles have dozens of oecus, heterogeneous vehicle networks [1, 2, 3], and external V2X communication channels for safety-critical and autonomous operations. This improvement dramatically increases vehicular attack surface and allows advanced driving. Wireless connectivity, software-defined components, and over-the-air updates interact with CAN domain communications, creating exponentially [4, 5, 6] complex protocol behaviour, vehicle status, and environmental context interdependencies in process. Thus, automobile network intrusion detection requires reasoning about complicated interconnections, temporal dynamics, and contextual semantics, not pattern recognition. Even though vehicular IDS research has evolved, basic assumptions limit it. Denial-of-service, spoofing, and fuzzing are considered static threats regardless of network structure. Detection pipelines usually flow from raw logs to supervised or deep learning models without assessing which threats are prevalent [10, 11, 12], how they propagate between oecus, or why some attacks persist despite mitigations. This omission decreases scientific interpretability and practical defensibility, especially in safety-regulated industries where failure modes are as important as detection accuracy. Second, vehicle data modelling is restricted. Assuming semantics persist throughout driving, payload bytes, message timing, and ECU interaction patterns are often merged into one feature space. Similar messages can be harmless while travelling but suspect during braking or congestion [13, 14, 15]. Channel load may induce timing irregularities, not adversarial intent. When deployed beyond controlled benchmarks, models that ignore contextual dependencies overfit to routes, traffic densities, or firmware versions, resulting in brittle performance. Current evaluation methods are also concerning. Most IDS research ends in accuracy, precision, or F1-score tables, not causal validity or resistance to realistic attack perturbations. A key gap is that an IDS that only detects assaults when multiple artefacts change may miss coordinated, subtle adjustments to preserve surfacelevel data. Few works discuss how to calibrate detection confidence for operational decisionmaking or adjust models to long-term drift from software upgrades, new oecus, or changing traffic conditions. Due to these issues, vehicle incursion detection should be rethought as a multistage reasoning process rather than a monolithic classifier. Effective protection requires structurally understanding the threat picture, learning context-aligned representations, detecting reliably under ambiguity, and verifying and maintaining the system during deployment. In its methodology, this work connects threat modelling, learning, robustness verification, and operational governance. Vehicular IDS goes from experimental accuracy-driven to deploymentgrade security using graph-based threat analysis, multi View contextual distillation, hybrid temporal–relational modelling, counterfactual verification, and drift-aware calibrations.

2. REVIEW OF EXISTING MODELS USED FOR ANALYSIS

Vehicle network intrusion detection research is shifting from lightweight, rule-driven defences to adaptive, learning-centric, and collaborative techniques. Jeyaram et al. [1] suggested a lightweight sequential AI system for real-time intrusion detection in dynamic vehicular environments in their current study. They solve vehicular network latency with temporal sequencing and computational efficiency. The system works effectively in real time, but it largely reads threats as temporal deviations, giving little structural reason for why some attacks survive under changing circumstances.

Lightweight deep learning architectures like Wang et al.’s MobileNetV3-based IDS emphasise efficiency and minimal models [2]. Adapting mobile vision networks to vehicular intrusion detection reduced computing cost and maintained competitive accuracy. The methodology abstracts vehicular communication as generic feature tensors without explicit reasoning about ECU interactions or protocol semantics,unlikearchitecture-driven methods. IoT intrusion detection was classified over extracted features by Bajpai et al. [3], but they made few vehicularspecific changes. Decentralised and cooperative vehicle networks spurred distributed learning and trust research. Mansouri et al. [4] created a blockchain-enabled, federated learning system for automobile ad hoc networks to protect privacy and decentralise trust. Collaborative detection, convergence stability, and delayed threat awareness were their findings. Game-theoretic

techniques like Anwar et al.’s hierarchical collaborative IDS [5] examined strategic interactions between cars and attackers, but their abstract payoff models were challenging to correlate with real-world vehicular data. Kamel et al. [6] developed important misbehaviour detection assessment frameworks for simulative validation rather than deployable learning pipelines.

In this nuanced review, Works like Vishnukumar and Ramaiah’s deep learning-based vehicle IDS [7] and the energy-efficient cluster-based IDS in vehicular ad hoc networks [16] give cautionary lessons. These occurrences emphasise the need for principled, explainable, and verifiable intrusion detection approaches due to field-wide reproducibility, dataset transparency, and assessment rigour issues. From 2021, research centred on optimisation, transfer learning, and hybrid intelligence. Alsarhan et al. [8] demonstrated machine learning-driven smart vehicle network optimisation, and Joseph et al. [9] combined quantum cryptography with machine learning-based IDS, demonstrating an increasing interest in post-classical security paradigms. Frimpong et al. [10] presented adaptive collaborative IDS methods for car fog computing that emphasise network edge scalability and adaptability. Some transfer learning approaches, suchas those by Mehedi et al. [11] and Rodríguez et al. [18], assume semantic validity across contexts despite little data and cross-domain generalisation. Recent studies incorporate protocol awareness and hierarchical learning. Smolin’sGenCoder++ framework improved vehicular communication semantics with protocol-aware and adversarially resilient detection for hybrid CAN–Ethernet networks [12]. Blockchain-enabled hierarchical federated approaches like Visuvanathan et al.’s BHFVAL [13] prioritised secure cooperation but increased system complexity. Comprehensive surveys like Nandy et al. [14] detail attack surfaces and IDS methods, fragmentingthe approach process.

Ragunthar et al. [21] improved machine learning-based anomaly detection and V2V protection, but largely by accuracy. Active learning, distributed invariants, and sampling trade-offs were studied together. Ahmed et al. [19] improved label efficiency but complicated software-defined vehicle network orchestration with deep active learning and load balancing. Distributed invariantbased detection by Zhou et al. [20] prevented localised errors, although emerging protocols made invariants harder to maintain. Kim & Kim [22] examined bandwidth–accuracy trade-offs in sampling-aware IDS design but not semantic ambiguity. Khan et al. [23] pioneered context-aware intrusion detection by modelling context and dataset augmentation to match driving situations. The field’s breadth but absence of a uniform analytical backbone is shown by supporting votingbased frameworks [24], lightweight in Vehicle IDS [25], industrial IoT vehicular security [26], federated cyberattack detection [27], signalling games [28], and ambient intelligence at the edge[29].

It was contrasted with three common starting points in order to demonstrate that the suggested framework was robust in comparison to the research that is currently being conducted: MLdriven optimisation IDS [8], kernel-based lightweight in-vehicle IDS [25], and general ML-based Internet of Things IDS [3] are the three classes of intrusion detection systems (IDS). This set of baselines was selected because, in the order listed above, they demonstrate feature-driven learning, optimization-centered intrusion detection system design, and lightweight application in cars. The proposed model achieved F1-scores ranging from 93.9 to 96.2% across a variety of driving scenarios, whilst the baselines remained within the range of 80.9 to 89.1% throughout the entire process. When there was a lot of traffic on the network, the suggested model cut down on false positives to 1.9% to 3.1%, compared to 4.6% to 9.1% for regular IDS behavior that doesn’t take context into account. It also had a detection delay of 18–27 ms and a throughput of about 940 windows per second, which was better than the lightweight baseline while keeping better detection accuracy. The framework kept 88.9–90.6% robust detection under minimal coordinated attack perturbations, while baseline methods stayed below 77%. The Expected Calibration Error was determined to have decreased to 0.03, and the performance retention after drift reached

95.6% thanks to this discovery. This demonstrates that the strategy provides improvements not only in terms of accuracy but also in terms of causal resilience, calibration quality, and operational stability.

Even while architectures, collaboration, and efficiency have improved, most research on detection accuracy ignores threat dominance, causal correctness, and long-term deployment governance. Lightweight models improve speed but restrict interpretability; federated and blockchain-based systems improve trust but complicate adaptability; context-aware techniques identify variability but lack threat prioritisation. Wang et al.’s latest lightweight ViT-based IDS [30] improves representational capacity but is model-centric. This work’s integrated paradigm synthesises rather than replaces previous advances. It directly addresses two-decade research gaps by learning from sequential models [1], lightweight architectures [2], collaborative detection [4,10], protocol awareness [12], and context modelling [23]. In contrast to static categorisation, vehicle intrusion detection is a lifecycle problem with explicit threat-graph reasoning, priorityguided multi-view distillation, reliability-aware hybrid detection, counterfactual verification, and drift-governed deployment [31,32]. It tackles the constraints mentioned in the literature and positions itself as a coherent, analytically informed field progression rather than a methodological increment set in process [33,34,35].This transfer learning-based intrusion detection framework [36] improves feature representation and classification in large-scale network traffic using Squeeze-and-Excitation (SE) networks and adaptive optimization. The proposed method detects cyber risks faster, more reliably, and more scalable in massive data environments. Several feature selection strategies improve intrusion detection system efficiency and effectiveness [37]. Ensemble feature selection reduces duplicate features and computational complexity, improving attack type classification accuracy.

3. PROPOSED MODEL DESIGN ANALYSIS

The analytical–learning pipeline mathematically links threat characterisation, representation alignment, detection, verification, and governance in the proposed integrated model process. Vehicle attacks are structured perturbations over time, topology, and protocol semantics (Figure 1); therefore, any successful IDS must reason about entropy, dynamics, and relationship causality. Represent the raw vehicle observation stream via Equation 1,

𝒳 = { 𝑥(𝑡) ∣ 𝑡 ∈ [0, 𝑇]}, 𝑥(𝑡) = (𝑝(𝑡), 𝜏(𝑡), 𝜅(𝑡), 𝑐(𝑡)) (1)

Where p(t) represents payload bytes, τ(t) inter-arrival duration, κ(t) topological ECU-message relations, and c(t) contextual factors including vehicle speed, brake state, road type, and channel loads. The pipeline employs context as a conditioning variable, not an auxiliary. In Figure 2, Threat-Graph Entropy Mining formalises the threat landscape as a directed interaction graph G=(V,E) with nodes for oecus, message identities, protocol states, and anomaly symptoms. A statistically significant causal influence from node ‘j’ under lag Δt suggests an edge eij∈Ein the process. Conditional mutual information via Equation 2 measures this influence,

𝐼( 𝑖 → 𝑗 ∣ 𝑐 ) == ∫ 𝑝( 𝑖𝑡 ,𝑗𝑡+Δ𝑡 ∣ 𝑐 )log ∫ 𝑝( 𝑗𝑡+Δ𝑡∣ ∣𝑖𝑡 , 𝑐 ) 𝑝( 𝑗𝑡+Δ𝑡∣ ∣𝑐 ) d𝑖𝑡 d𝑗𝑡+Δ𝑡 (2)

For each attack family 𝑎, payload–timing uncertainty is captured through entropy accumulation Via equation 3,

𝐻𝑎 = −𝑝𝑎 (Δ𝑡, 𝑝)log ∫ 𝑝𝑎 (Δ𝑡, 𝑝) dΔ𝑡 d𝑝 (3)

While structural dominance is measured through graph centrality 𝐶𝑎(𝐺) sets. These are fused into a Threat Dominance Score Via equation 4,

Leave a Reply

Information

This entry was posted on October 11, 2026 by .

Navigation